Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1080 commits
Select commit Hold shift + click to select a range
52d5a3f
Clarify attachment alt text help
BagToad Aug 25, 2026
6c46619
Correct attachment conflict caller
BagToad Aug 25, 2026
fb6d377
Rename attachment argument slice
BagToad Aug 25, 2026
bb63c24
Preserve markdown for empty additions
BagToad Aug 25, 2026
886af95
Clarify comment attachment help
BagToad Aug 25, 2026
6abc068
Separate comment test case braces
BagToad Aug 25, 2026
49e92c2
Document permission-aware repository stub
BagToad Aug 25, 2026
ae5d443
Document partial PR attachment outcomes
BagToad Aug 25, 2026
912e411
Remove redundant prompt failure stubs
BagToad Aug 25, 2026
c81d081
Document partial issue attachment outcomes
BagToad Aug 25, 2026
eb9839e
Validate issue type before uploads
BagToad Aug 25, 2026
ac2222a
Test editor attachment rewriting
BagToad Aug 25, 2026
cd94f8c
Remove redundant issue prompt stub
BagToad Aug 25, 2026
c218854
Add attachment flag wrapper
BagToad Aug 25, 2026
9dc818d
Move attachment policy into commands
BagToad Aug 25, 2026
fe4c3cb
chore(deps): bump github.com/sigstore/protobuf-specs from 0.5.1 to 0.5.2
dependabot[bot] Aug 25, 2026
b9908d1
Support PI_CODING_AGENT_DIR for skills
tommaso-moro Aug 25, 2026
b061fc4
Document attachment support in gh skill
BagToad Aug 25, 2026
a18c1bc
Reject comments with JSON output
BagToad Aug 20, 2026
c2b23c8
Clarify rate limit retry units
BagToad Aug 25, 2026
22769b5
Document attachment path resolution
BagToad Aug 25, 2026
cc83172
Merge pull request #14262 from cli/bagtoad/sturdy-funicular
BagToad Aug 25, 2026
53c733c
test: cover non-empty worktree target rejection
babakks Aug 26, 2026
9e69e88
Merge pull request #14244 from cli/tidy-dev-worktree-checkout-feedback
babakks Aug 26, 2026
a99100c
test(repo sync): add single-worktree repo sync acceptance test
babakks Aug 26, 2026
c2c3572
test(repo sync): group non-current-branch sync tests into subtests
babakks Aug 26, 2026
e2fcbf7
fix(repo sync): surface worktree lookup error alongside update failure
babakks Aug 26, 2026
a2fd23c
Merge pull request #14060 from cli/12927-fix-repo-sync-worktree
babakks Aug 26, 2026
2ff7220
docs(gh-skill): document gh issue develop --checkout --worktree
babakks Aug 26, 2026
606cda4
Merge pull request #14265 from cli/babakks/add-issue-develop-worktree…
babakks Aug 26, 2026
3f5ef1f
chore(deps): bump github.com/google/go-containerregistry
dependabot[bot] Aug 26, 2026
6e1904a
chore(deps): bump the codeql-actions group across 1 directory with 3 …
dependabot[bot] Aug 26, 2026
e954245
Replace interface{} with any
BagToad Aug 26, 2026
abdea37
Use fmt.Appendf for byte formatting
BagToad Aug 26, 2026
4f0eb3d
Use maps helpers for map loops
BagToad Aug 26, 2026
aee884d
Use min and max built-ins
BagToad Aug 26, 2026
3f7bb81
Use new expression syntax
BagToad Aug 26, 2026
8a63c38
Use omitzero JSON tags
BagToad Aug 26, 2026
e26caf1
Use integer range loops
BagToad Aug 26, 2026
83c1649
Use reflect.TypeFor
BagToad Aug 26, 2026
6f844ce
Use slices.Contains helpers
BagToad Aug 26, 2026
fdd5a07
Use standard library iterators
BagToad Aug 26, 2026
fc68dc4
Use strings.Builder for concatenation
BagToad Aug 26, 2026
d190d6a
Use strings.Cut
BagToad Aug 26, 2026
4cf0c4e
Use strings.CutPrefix
BagToad Aug 26, 2026
f0f3646
Use string sequence iterators
BagToad Aug 26, 2026
556199d
Use testing context helper
BagToad Aug 26, 2026
ecb8c5a
Use WaitGroup.Go
BagToad Aug 26, 2026
0b23d8d
Inline duration pointer helper
BagToad Aug 26, 2026
b3846d7
Apply remaining strings.Builder fix
BagToad Aug 26, 2026
981de3e
Run go fix in lint workflow
BagToad Aug 26, 2026
6ba9230
Remove inlined pointer helpers
BagToad Aug 26, 2026
e86515a
Remove obsolete reflection helper
BagToad Aug 26, 2026
7ca1a75
Merge pull request #14215 from cli/bagtoad/fix-issue-comments-json
BagToad Aug 27, 2026
09bf3ff
Merge pull request #14247 from cli/dependabot/go_modules/google.golan…
williammartin Aug 27, 2026
2e9fccb
Merge pull request #14248 from cli/dependabot/go_modules/charm.land/b…
williammartin Aug 27, 2026
19b17f9
Merge pull request #14250 from cli/dependabot/github_actions/codeql-a…
williammartin Aug 27, 2026
5388029
chore(deps): bump charm.land/bubbles/v2 from 2.1.1 to 2.2.0
dependabot[bot] Aug 27, 2026
3d63471
Merge pull request #14249 from cli/dependabot/go_modules/charm.land/b…
williammartin Aug 27, 2026
ee05802
Clarify PR testing guidance
williammartin Aug 27, 2026
e248b92
Merge pull request #14272 from cli/williammartin-truthful-pr-testing
williammartin Aug 27, 2026
3bc8eaa
Merge pull request #14271 from cli/williammartin-fix-spam-triage-labe…
williammartin Aug 27, 2026
19fe972
Bump agentic-workflows to 0.87.5
williammartin Aug 27, 2026
2c5ff72
Merge pull request #14273 from cli/wm-bump-aw
williammartin Aug 27, 2026
33edc00
Do not allow dependabot to bump aw
williammartin Aug 27, 2026
9610177
chore(deps): bump charm.land/bubbles/v2 from 2.2.0 to 2.2.1
dependabot[bot] Aug 27, 2026
d76da60
Merge pull request #14274 from cli/wm-aw-dependabot
williammartin Aug 27, 2026
07fb593
Use native Go diff checks
BagToad Aug 27, 2026
10f0ee3
Simplify skill processing limit
BagToad Aug 27, 2026
a0b4ede
Simplify auth host validation
BagToad Aug 27, 2026
4c32c17
Inline codespace slice checks
BagToad Aug 27, 2026
88684c2
Inline pull request slice checks
BagToad Aug 27, 2026
2ea4611
Merge pull request #14278 from cli/bagtoad/go-fix-cleanup
BagToad Aug 27, 2026
679018a
Merge pull request #14275 from cli/dependabot/go_modules/charm.land/b…
williammartin Aug 28, 2026
8d17165
Merge pull request #14258 from cli/dependabot/go_modules/github.com/s…
williammartin Aug 28, 2026
9b323de
Merge pull request #14267 from cli/dependabot/go_modules/github.com/g…
williammartin Aug 28, 2026
f2bf7c3
Limit attachment batches to 50 files
BagToad Aug 28, 2026
40b742f
Merge pull request #14289 from cli/bagtoad/limit-attachment-batches
BagToad Aug 28, 2026
367d30a
chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2
dependabot[bot] Aug 31, 2026
78aaae9
chore(deps): bump the codeql-actions group with 3 updates
dependabot[bot] Aug 31, 2026
5d0f7d7
chore(deps): bump azure/login from 3.0.1 to 3.0.2
dependabot[bot] Aug 31, 2026
0574bc5
Merge pull request #14299 from cli/dependabot/go_modules/google.golan…
sergiou87 Sep 1, 2026
35f596d
Merge pull request #14301 from cli/dependabot/github_actions/azure/lo…
sergiou87 Sep 1, 2026
a8460b5
Merge pull request #14300 from cli/dependabot/github_actions/codeql-a…
sergiou87 Sep 1, 2026
e909b95
Merge pull request #14154 from scarletkc/scarletkc/fix-codex-user-ski…
BagToad Sep 1, 2026
d528f20
Merge pull request #14260 from cli/tommaso-moro-support-pi-agent-dire…
BagToad Sep 1, 2026
71eac35
Merge pull request #14198 from cli/niik-agent-full-help-on-error
niik Sep 2, 2026
7be4c29
Fix discussion acceptance test flags
williammartin Sep 2, 2026
0da5ee8
Merge pull request #14321 from cli/williammartin-fix-discussion-accep…
williammartin Sep 2, 2026
c219743
Add acceptance coverage for gist
williammartin Aug 7, 2026
bceaa3b
Wait longer for the search index in the issues script
williammartin Aug 7, 2026
0f3ab22
Let GH_ACCEPTANCE_SCRIPT name several scripts
williammartin Aug 7, 2026
eae00d0
Add the api_host gateway harness
williammartin Aug 7, 2026
3189464
Send a host's token to its configured api_host
williammartin Aug 7, 2026
2d89b26
Make gh api honour api_host for relative paths
williammartin Aug 7, 2026
670b2a3
Send RenameRepo to a relative path
williammartin Aug 7, 2026
62a6e9e
Add a raw response request surface to api.Client
williammartin Aug 7, 2026
216199e
Let a caller name the scopes an endpoint needs
williammartin Aug 7, 2026
eae1deb
Let a caller stop a request following redirects
williammartin Aug 7, 2026
6fcf2ea
Let callers set headers on a shared client request
williammartin Aug 7, 2026
ffb187b
Send release asset uploads and downloads through api.Client
williammartin Aug 7, 2026
97fcb73
docs(api): clarify redirect method-rewriting in comments
babakks Aug 27, 2026
dbbaed8
fix(config): resolve api_host collisions deterministically
babakks Aug 27, 2026
fbda842
refactor(api): use errors.AsType for HTTP error checks
babakks Aug 27, 2026
d5ff05b
test(acceptance): cover selecting multiple scripts in one directory
babakks Aug 27, 2026
c67d0e6
test(api): assert DoRequest preserves an explicit ContentLength
babakks Aug 27, 2026
2266020
test(config): cover deterministic api_host collision resolution
babakks Aug 27, 2026
62f5a7c
test(config): add coverage for APIHostForHost
babakks Aug 27, 2026
061b2a1
fix(auth/shared): route GetScopes path through safeurl
babakks Aug 27, 2026
fcd05d9
chore(codeql): cover api.Client.Request in SafeURL path query
babakks Aug 27, 2026
4288f57
build(deps): bump go-gh to per-host api_host branch
babakks Aug 27, 2026
95107ff
test(acceptance): fix scriptfilter table field alignment
babakks Aug 27, 2026
48922ac
fix(api): compare request hostname without port when attaching auth t…
babakks Aug 28, 2026
ee5ed71
chore: tidy go.sum
babakks Aug 28, 2026
e7675c9
test(internal/attachments): add new method required by interface
babakks Aug 28, 2026
061e585
chore: apply go fix
babakks Aug 28, 2026
2f88d05
refactor(attachments): send uploads through api.Client.DoRequest
babakks Aug 28, 2026
6656e47
build(deps): bump go-gh to rebased per-host api_host branch
babakks Aug 28, 2026
fe76ff5
Rename tokenGetter to config
williammartin Sep 2, 2026
628e85c
Refactor AddAuthTokenHeader
williammartin Sep 2, 2026
714e5ea
Document when telemetry disabling is overzealous
williammartin Sep 2, 2026
8b3e2f1
Comment missing api-client-rollout todo
williammartin Sep 2, 2026
5ba76c6
Comment api command api_host usage
williammartin Sep 2, 2026
6e7b1fe
Remove redundant comment in gist create
williammartin Sep 2, 2026
0580da9
Remove unnecessary 204 on release edit
williammartin Sep 2, 2026
05a0a02
Remove redundant searcher comment
williammartin Sep 2, 2026
6865464
Bump go-gh to v2.15.0
williammartin Sep 2, 2026
905e868
Clarify supported GHES versions
williammartin Sep 2, 2026
09850d5
Use version-neutral GHES support link
williammartin Sep 2, 2026
b94691d
Refine GHES support wording
williammartin Sep 2, 2026
9d36fee
Merge pull request #14324 from cli/williammartin-github-mercy-preview
williammartin Sep 2, 2026
a82d1e9
Merge pull request #14318 from cli/issue-triage-improvements
sergiou87 Sep 2, 2026
adda317
Merge pull request #14104 from cli/williammartin-api-host-commit-split
williammartin Sep 2, 2026
d00109a
Add webhook as an official extension
williammartin Sep 2, 2026
5b02f9a
Record attachment invocation telemetry
BagToad Sep 2, 2026
ad5677b
chore: bump golang.org/x/crypto to 0.56.0
babakks Sep 3, 2026
8e55608
Merge pull request #14331 from cli/babakks/bump-crypto
williammartin Sep 3, 2026
f942759
chore: bump toolchain to go1.26.8
babakks Sep 3, 2026
636cbb6
Merge pull request #14326 from cli/wm-add-webhook-as-official-extension
williammartin Sep 3, 2026
a609c2b
Merge pull request #14330 from cli/babakks/bump-go
babakks Sep 3, 2026
d4d6e70
Add trustworthy VHS demo skill
williammartin Sep 3, 2026
bf19e9c
Expose per-host API host config
williammartin Sep 3, 2026
9a6b96d
Merge pull request #14332 from cli/williammartin-config-api-host
williammartin Sep 3, 2026
6e82bc5
Merge pull request #14327 from cli/bagtoad/attach-flag-metrics
BagToad Sep 3, 2026
90b3db0
Bump go-gh to v2.16.0
williammartin Sep 3, 2026
bac1b1b
Merge pull request #14338 from cli/wm/bump-go-gh-to-2.16.0
williammartin Sep 3, 2026
4a75987
Fix gh api telemetry disablement
williammartin Sep 3, 2026
45437bc
Merge pull request #14337 from cli/williammartin-ghes-api-telemetry
williammartin Sep 3, 2026
ef30455
docs: announce Linux PGP key rotation
babakks Sep 3, 2026
e63f614
Merge pull request #14340 from cli/babakks/hint-at-pgp-key-rotation
babakks Sep 3, 2026
92029a9
Require verified commit SHAs in issue-triage permalinks
sergiou87 Sep 4, 2026
400c084
Merge pull request #14343 from cli/issue-triage-permalinks
sergiou87 Sep 4, 2026
cbe0458
Add clipboard preference for auth flows
williammartin Sep 4, 2026
03740ac
Use API SSH URLs for repository clones
williammartin Sep 4, 2026
77e282e
Guard repository query selections
williammartin Sep 4, 2026
c11b702
Preserve host-scoped config compatibility
williammartin Sep 4, 2026
e316a01
Enable clipboard auth by default
williammartin Sep 4, 2026
b174ed5
Fix VHS evidence inspection
williammartin Sep 4, 2026
6de236a
Apply Go fixes to changed packages
williammartin Sep 4, 2026
d2637ff
Tighten quality gate guidance
williammartin Sep 4, 2026
69e69c1
Fix Go bump workflow toolchain
williammartin Sep 4, 2026
2ea56b1
Clear legacy enterprise token
williammartin Sep 4, 2026
965c3dd
Merge pull request #14345 from cli/williammartin-issue-13153-plan
williammartin Sep 4, 2026
cba9646
Merge pull request #14334 from cli/williammartin-refine-vhs-demo-skill
williammartin Sep 4, 2026
41b7d3c
Validate automated Go version bumps
williammartin Sep 4, 2026
fda2d61
Defer Go source migrations to bump
williammartin Sep 4, 2026
3e3eb86
Resolve linter version during Go bumps
williammartin Sep 4, 2026
05dee02
Keep Go bump inputs scoped
williammartin Sep 4, 2026
6232ed1
Harden Go bump version and cleanup
williammartin Sep 4, 2026
a73c594
Check normalized Go state for lint bump
williammartin Sep 4, 2026
091c24d
Record attachment operation counts
BagToad Sep 4, 2026
31e1704
Merge pull request #14346 from cli/williammartin-ssh-certificate-auth…
williammartin Sep 5, 2026
a6cb3e8
docs: fix broken "GitHub language" link in primer foundations
areesh-ali Sep 5, 2026
c9dd6db
Merge pull request #14363 from areesh-ali/docs-fix-primer-github-lang…
williammartin Sep 5, 2026
0d121e8
Merge pull request #14347 from cli/williammartin-fix-agentic-workflow
williammartin Sep 5, 2026
145d839
chore(deps): bump github.com/microsoft/dev-tunnels from 0.1.27 to 0.2.0
dependabot[bot] Sep 7, 2026
2091aae
chore(deps): bump github.com/klauspost/compress from 1.19.2 to 1.20.0
dependabot[bot] Sep 7, 2026
123c1e7
chore(deps): bump github.com/google/go-containerregistry
dependabot[bot] Sep 7, 2026
5a7c407
chore(deps): bump github.com/yuin/goldmark from 1.8.5 to 1.8.6
dependabot[bot] Sep 7, 2026
f537efa
Rewrite CLI agent guidance
williammartin Sep 8, 2026
5aef01f
docs: update release deep dive for new PGP signing key
Copilot Sep 8, 2026
d6cbbe9
Share development guides across contributors
williammartin Sep 8, 2026
111b254
Merge pull request #14197 from cli/babakks/single-sign-with-new-pgp-key
babakks Sep 8, 2026
5e078ed
finalize telemetry at invocation completion
williammartin Sep 8, 2026
20c599b
chore(deps): bump golang.org/x/sync from 0.22.0 to 0.23.0
dependabot[bot] Sep 8, 2026
46e09a5
separate event recording from invocation policy
williammartin Sep 8, 2026
7f3b491
send telemetry when invocation finishes
williammartin Sep 8, 2026
c41dd03
restore telemetry service naming
williammartin Sep 8, 2026
570183b
rename telemetry BeginEvent to Begin
williammartin Sep 8, 2026
0710596
move service back into telemetry.go
williammartin Sep 8, 2026
3c517fa
limit telemetry disabling to the service
williammartin Sep 8, 2026
03acc10
name pending telemetry updates as upserts
williammartin Sep 8, 2026
38a05c9
Merge pull request #14388 from cli/williammartin-rewrite-cli-agent-gu…
williammartin Sep 8, 2026
2ac2543
simplify attachment telemetry initialization
williammartin Sep 8, 2026
14fc1ff
minimize incidental telemetry service changes
williammartin Sep 8, 2026
75fc31e
Prepare exit errors for Go 1.27
williammartin Sep 8, 2026
707514f
Merge pull request #14397 from cli/williammartin-fix-agentic-workflow
williammartin Sep 8, 2026
d2fe6e9
start attachment telemetry before asset validation
williammartin Sep 8, 2026
3870413
use typed attachment telemetry events
williammartin Sep 8, 2026
d9b962e
Share acceptance fixture repositories
williammartin Sep 4, 2026
109807c
Reduce acceptance repository creation
williammartin Sep 4, 2026
3a82177
Avoid redundant acceptance clones
williammartin Sep 4, 2026
d1e2960
Enable discussions in shared fixture
williammartin Sep 4, 2026
8d44b27
Address acceptance fixture review
williammartin Sep 8, 2026
f39af8a
Reduce acceptance test contention
williammartin Sep 8, 2026
b5eb79f
Synchronize acceptance test operations
williammartin Sep 8, 2026
040ddb0
Harden acceptance test isolation
williammartin Sep 8, 2026
7f58f91
Tighten acceptance feedback loop
williammartin Sep 8, 2026
118e348
Restore acceptance test coverage
williammartin Sep 8, 2026
dcef13b
Improve acceptance linter guidance
williammartin Sep 8, 2026
24e9144
Harden acceptance resource readiness
williammartin Sep 8, 2026
be67f31
Explain renamed repository cleanup
williammartin Sep 9, 2026
3c0f54c
Improve workflow timeout diagnostics
williammartin Sep 9, 2026
b54469f
simplify telemetry test coverage
williammartin Sep 9, 2026
81780e7
simplify telemetry recording and tests
williammartin Sep 9, 2026
89f0561
Consolidate secret workflow coverage
williammartin Sep 9, 2026
1f6b063
Retry conflicting repository renames
williammartin Sep 9, 2026
1ba640d
clarify attachment tests and telemetry state
williammartin Sep 9, 2026
cf2f3fc
Keep repository rename test explicit
williammartin Sep 9, 2026
734a22c
Stabilize variable list assertions
williammartin Sep 9, 2026
9a16764
Reuse workflow dispatch run IDs
williammartin Sep 9, 2026
9b6585b
Reduce rate limiting and reduce time taken for acceptance tests (#14320)
williammartin Sep 9, 2026
6dc60bf
Filter acceptance tests by token capability
williammartin Sep 4, 2026
7901e7e
Address acceptance capability review
williammartin Sep 9, 2026
9174ffb
Validate repository names during interactive creation (#14313)
sergiou87 Sep 9, 2026
e18cc33
Merge pull request #14354 from cli/williammartin-acceptance-token-cap…
williammartin Sep 9, 2026
3041965
Propagate gh path to extensions
williammartin Aug 28, 2026
c708a53
Remove GH_EXTENSION help text per review feedback
Copilot Sep 9, 2026
983071a
Restore GH_EXTENSION and GH_PATH help entries
Copilot Sep 9, 2026
ae1ba32
Merge pull request #14390 from cli/williammartin-wm-invocation-telemetry
BagToad Sep 9, 2026
093c348
Merge pull request #14282 from cli/williammartin-propagate-gh-path-to…
williammartin Sep 9, 2026
cebba8c
Merge pull request #14412 from cli/williammartin-fix-workflow-failure
williammartin Sep 10, 2026
c265dd8
Run acceptance tests in Actions with a GitHub App token (#14356)
williammartin Sep 10, 2026
3b3093f
Fix acceptance script paths on Windows
williammartin Sep 10, 2026
0ba226a
Fix acceptance script paths on Windows (#14414)
williammartin Sep 10, 2026
07e9065
Wait for repository before archiving
williammartin Sep 10, 2026
5448cdc
Delete repo garden command
williammartin Sep 10, 2026
f073783
Merge pull request #14415 from cli/williammartin-investigate-archive-…
williammartin Sep 10, 2026
411dce4
Merge pull request #14376 from cli/dependabot/go_modules/github.com/k…
williammartin Sep 10, 2026
abd3967
Merge pull request #14377 from cli/dependabot/go_modules/github.com/g…
williammartin Sep 10, 2026
66ae8d8
Merge pull request #14378 from cli/dependabot/go_modules/github.com/y…
williammartin Sep 10, 2026
2a9fb1d
Merge pull request #14391 from cli/dependabot/go_modules/golang.org/x…
williammartin Sep 10, 2026
9a779be
chore(deps): bump golang.org/x/sys from 0.47.0 to 0.48.0
dependabot[bot] Sep 10, 2026
b621996
Merge pull request #14375 from cli/dependabot/go_modules/github.com/m…
williammartin Sep 10, 2026
6dec969
Merge pull request #14417 from cli/dependabot/go_modules/golang.org/x…
williammartin Sep 10, 2026
7b2de63
Merge pull request #14416 from cli/wm-delete-repo-garden
williammartin Sep 10, 2026
d171a91
Update Go bump validation tools
williammartin Sep 11, 2026
7f0590c
Merge pull request #14428 from cli/williammartin-investigate-ci-panic
williammartin Sep 11, 2026
8fcd6a6
Fix remote branch deletion for owner case mismatch (#14429)
williammartin Sep 11, 2026
ba51bb4
Retire multi-account migration (#14430)
williammartin Sep 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"image": "mcr.microsoft.com/devcontainers/go:1.25",
"image": "mcr.microsoft.com/devcontainers/go:1.26",
"features": {
"ghcr.io/devcontainers/features/sshd:1": {}
},
Expand Down
73 changes: 73 additions & 0 deletions .experiments/tech-debt-burndown/memory.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
# Tech debt burndown: agent memory

Standing corrections for the [`tech-debt-burndown` skill](../../.github/skills/tech-debt-burndown/SKILL.md).
This file is loaded at the start of every run and is binding.
Both humans and agent runs write here, and nothing distinguishes the two once
written. Assume any entry may be an unreviewed conclusion from a previous run.
Entries are binding on what to avoid; factual claims in them should be
re-verified before you lean on them, and corrected when stale. Date-stamp
anything you add.

**Budget: 150 lines of entries**, counted from the end of Current focus to the end
of the file. The header and Current focus do not count, and must never be trimmed
to get under budget: they are instructions, not findings. If an append would
exceed the budget, consolidate existing entries first, in the same pull request.

The budget exists so this file stays worth reading, not to save tokens - the
skill file is several times longer. A memory file that has become a run log is
one nobody reads carefully, including you.

## Current focus

**Human-owned. Agent runs must not edit this section.** Propose changes in the
pull request body instead.

Empty. With no focus set, runs fall back to the tier order in the skill.

<!-- Examples of what can go here:
- "Work on pkg/cmd/pr/edit until staticcheck is clean, then add the exclusion."
- "Prefer skipped tests and stale nolints over linter findings for now."
- "Leave staticcheck alone, it is all cosmetic. Focus on errcheck." -->

## Off limits

- Generated code and mocks. See the Never touch section of the skill.
- Removing a feature-detection gate (`// TODO <cleanupIdentifier>`). Whether a
gate can come out depends on the supported GHES version window, which is not
discoverable from the repo and cannot be resolved unattended.

## Known scale of the linter backlog

Counts measured by an agent run on 2026-08-06 against `trunk`, not verified by a
human, and stale as soon as anything lands. Use them to choose between linters,
not as a target count. Command: `--no-config --default=none
--max-issues-per-linter=0 --max-same-issues=0`, so this repo's exclusions are
*not* applied and these are upper bounds: errcheck 1245, staticcheck 221,
gosec 435.

`gosec` is the least tractable, because `.golangci.yml` already excludes G110,
G204, G301, G302, G304, G307, and G404, plus all `gosec` findings in `_test.go`
files, and a `--no-config` run reports all of those anyway. Always cross-check
`gosec` output against `.golangci.yml` before acting on it.

## Staticcheck shape

2026-08-06: repo-wide staticcheck has **no `SA` (correctness) findings**. It is
all style: QF1008 (70), QF1012 (50), ST1005 (29), QF1003 (24), ST1012 (16), rest
single digits. Staticcheck targets are mechanical and safe, but low value.

Most-affected packages: `pkg/cmd/pr/edit` (23), `pkg/cmd/issue/edit` (19),
`pkg/cmd/auth/status` (16), `pkg/cmd/extension` (11). `pkg/cmd/alias/imports` was
cleared 2026-08-06.

## Rejected targets

None yet.

## False positives

None yet.

## Failed attempts

None yet.
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -1 +1,3 @@
.github/actions/*/lib/* linguist-generated

.github/workflows/*.lock.yml linguist-generated=true
20 changes: 11 additions & 9 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,15 +1,17 @@
* @cli/code-reviewers

pkg/cmd/codespace/ @cli/codespaces
internal/codespaces/ @cli/codespaces
pkg/cmd/codespace/ @cli/codespaces @cli/code-reviewers
internal/codespaces/ @cli/codespaces @cli/code-reviewers

# Limit Package Security team ownership to the attestation command package and related integration tests
pkg/cmd/attestation/ @cli/package-security
pkg/cmd/release/attestation/ @cli/package-security
pkg/cmd/release/verify/ @cli/package-security
pkg/cmd/release/verify-asset/ @cli/package-security
pkg/cmd/release/shared/ @cli/package-security
pkg/cmd/attestation/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/verify/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/verify-asset/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/shared/ @cli/package-security @cli/code-reviewers

test/integration/attestation-cmd @cli/package-security
test/integration/attestation-cmd @cli/package-security @cli/code-reviewers

pkg/cmd/attestation/verification/embed/tuf-repo.github.com/ @cli/tuf-root-reviewers
pkg/cmd/attestation/verification/embed/tuf-repo.github.com/ @cli/tuf-root-reviewers @cli/code-reviewers

pkg/cmd/skills/ @cli/skills @cli/code-reviewers
internal/skills/ @cli/skills @cli/code-reviewers
6 changes: 3 additions & 3 deletions .github/CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

Hi! Thanks for your interest in contributing to the GitHub CLI!

We accept pull requests for issues labelled `help wanted`. We encourage issues and discussion posts for all other contributions.
We accept external pull requests only for issues labelled `help wanted` with explicit Acceptance Criteria. We encourage issues and discussion posts for all other contributions. For security concerns, follow our [private disclosure policy](SECURITY.md) instead.

### Please do:

Expand All @@ -12,7 +12,7 @@ We accept pull requests for issues labelled `help wanted`. We encourage issues a
* Open an issue to propose a design for an issue labelled [`needs-design` and `help wanted`][needs design and help wanted], following the [proposing a design guidelines](#proposing-a-design) instructions below
* Open an issue to propose a new community supported `gh` package with details about support and redistribution
* Mention `@cli/code-reviewers` when an issue you want to work on does not have clear Acceptance Criteria
* Open a pull request for any issue labelled [`help wanted`][hw] and [`good first issue`][gfi]
* Open a pull request for an issue labelled [`help wanted`][hw] with explicit Acceptance Criteria. Issues labelled [`good first issue`][gfi] must also meet these requirements

### Please _do NOT_:

Expand All @@ -36,7 +36,7 @@ Run the new binary as:

Run tests with: `go test ./...`

See [project layout documentation](../docs/project-layout.md) for information on where to find specific source files.
See the [development guides](../docs/README.md) for project layout, command conventions, testing, and API/host behavior.

## Submitting a pull request

Expand Down
76 changes: 74 additions & 2 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,76 @@
<!--
Thank you for contributing to GitHub CLI!
To reference an open issue, please write this in your description: `Fixes #NUMBER`
Thank you for contributing to GitHub CLI!

If you are proposing a fix for a security issue, STOP and follow .github/SECURITY.md instead.
-->

<!-- List related issues here. Use `fixes` or `closes` keywords to associate an issue number. -->

### Description

<!--
What's the problem? How are we addressing it?

Write for a reviewer who has not worked in this part of the codebase. Give them the
background they need before the problem makes sense, and avoid jargon.
-->

### How did you test this change?

<!--
Report only actions you actually performed and results you actually observed, using factual
first-person language (for example, "I ran..." and "I saw..."). Do not present planned,
hypothetical, inferred, or merely expected scenarios as testing.

Automated test results do not belong here. Passing unit tests, `go test ./...` output, and
coverage numbers tell a reviewer nothing they cannot see from CI, so do not paste them.

If you did not exercise the changed behavior, write `Not tested` and explain why.

Use one or more of these, whichever communicates best:

1. Screenshots or GIFs of the real command running. Preferred whenever the change is visible
in terminal output. If output changed, show it before and after.
2. Given/When/Then scenarios, but only when you actually executed the steps. For example:
Given I was in a repo with no open pull requests
When I ran `gh pr list`
Then I saw "no open pull requests in cli/cli"
3. A natural language walkthrough of what you did by hand, the states you covered, and what
you saw, including error and edge cases.

If you leave this empty, your pull request will very likely be closed.
-->

### Key points

<!--
Tradeoffs you accepted, alternatives you rejected, and anything a reviewer would otherwise have to guess at.
-->

### Notes for reviewers

<!--
Where should review start, and what should be read next? Call out anything you are unsure about.

Link related issues or prior discussion, with one sentence on why each matters.
-->

### Authorship and follow-up

<!--
REQUIRED - If you are an AI agent filling in this template, answer "Who wrote this" for yourself and answer honestly. For "Who answers review comments," use only a choice the human has explicitly made in the conversation. If no choice has already been established, pause and ask the human to choose one of the three options before creating or updating the pull request. Do not infer the choice from repository ownership, authorship, assignees, prior interactions, or the current operator. After the human answers, check exactly the option they chose; the last option is valid when the human explicitly chooses nobody.

Check exactly one box in each list.
-->

Who wrote this:

- [ ] A human wrote it.
- [ ] An agent wrote it under close human direction.
- [ ] An agent wrote it independently, and no human has guided the implementation beyond the initial prompt.

Who answers review comments:

- [ ] @username will read and reply directly. Name the account.
- [ ] An agent will draft replies and @username will read them before they are posted.
- [ ] Nobody has explicitly committed to replying.
Loading